Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228421 5 警告 xerver - Xerver HTTP Server における Web ページに対するソースコードを取得される脆弱性 CWE-200
情報漏えい
CVE-2009-3544 2012-12-20 19:28 2009-10-5 Show GitHub Exploit DB Packet Storm
228422 7.5 危険 phpgenealogy - PHPGenealogy の CoupleDB.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3541 2012-12-20 19:28 2009-10-2 Show GitHub Exploit DB Packet Storm
228423 4.3 警告 YourFreeWorld.com - YourFreeWorld Ultra Classifieds Pro の listads.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3540 2012-12-20 19:28 2009-10-2 Show GitHub Exploit DB Packet Storm
228424 4.3 警告 YourFreeWorld.com - YourFreeWorld Ultra Classifieds Pro におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3539 2012-12-20 19:28 2009-10-2 Show GitHub Exploit DB Packet Storm
228425 7.5 危険 universe - Universe CMS の vnews.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3531 2012-12-20 19:28 2009-10-2 Show GitHub Exploit DB Packet Storm
228426 4.3 警告 radscripts - RadScripts RadBids Gold の storefront.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3530 2012-12-20 19:28 2009-10-2 Show GitHub Exploit DB Packet Storm
228427 6.8 警告 radscripts - RadScripts RadBids Gold の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3529 2012-12-20 19:28 2009-10-2 Show GitHub Exploit DB Packet Storm
228428 4.3 警告 pilotgroup - PG eTraining におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3513 2012-12-20 19:28 2009-10-1 Show GitHub Exploit DB Packet Storm
228429 4.3 警告 phplemon - MyWeight におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3512 2012-12-20 19:28 2009-10-1 Show GitHub Exploit DB Packet Storm
228430 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech MMORPG Zone の view_news.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3505 2012-12-20 19:28 2009-09-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
216231 5.3 MEDIUM
Network
paessler prtg_network_monitor PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal stat… CWE-306
Missing Authentication for Critical Function
CVE-2020-11547 2024-11-21 13:58 2020-04-5 Show GitHub Exploit DB Packet Storm
216232 9.8 CRITICAL
Network
3xlogic infinias_eidc32_firmware
infinias_eidc32_web
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring. CWE-287
CWE-319
Improper Authentication
Cleartext Transmission of Sensitive Information
CVE-2020-11542 2024-11-21 13:58 2020-04-5 Show GitHub Exploit DB Packet Storm
216233 5.5 MEDIUM
Local
ivanti workspace_control Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material). NVD-CWE-noinfo
CVE-2020-11533 2024-11-21 13:58 2020-04-5 Show GitHub Exploit DB Packet Storm
216234 6.1 MEDIUM
Network
getgrav grav Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x. CWE-601
Open Redirect
CVE-2020-11529 2024-11-21 13:58 2020-04-5 Show GitHub Exploit DB Packet Storm
216235 7.5 HIGH
Network
bit2spr_project bit2spr bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file. CWE-787
 Out-of-bounds Write
CVE-2020-11528 2024-11-21 13:58 2020-04-5 Show GitHub Exploit DB Packet Storm
216236 7.5 HIGH
Network
zohocorp manageengine_opmanager In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files. NVD-CWE-noinfo
CVE-2020-11527 2024-11-21 13:58 2020-04-5 Show GitHub Exploit DB Packet Storm
216237 9.8 CRITICAL
Network
zohocorp manageengine_adselfservice_plus Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution. NVD-CWE-noinfo
CVE-2020-11518 2024-11-21 13:58 2020-04-4 Show GitHub Exploit DB Packet Storm
216238 7.4 HIGH
Network
gnu
debian
opensuse
canonical
fedoraproject
gnutls
debian_linux
leap
ubuntu_linux
fedora
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' by… CWE-330
 Use of Insufficiently Random Values
CVE-2020-11501 2024-11-21 13:58 2020-04-3 Show GitHub Exploit DB Packet Storm
216239 7.5 HIGH
Network
zoom meetings Zoom Client for Meetings through 4.6.9 uses the ECB mode of AES for video and audio encryption. Within a meeting, all participants use a single 128-bit key. CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-11500 2024-11-21 13:58 2020-04-3 Show GitHub Exploit DB Packet Storm
216240 6.1 MEDIUM
Network
firmware_analysis_and_comparison_tool_project firmware_analysis_and_comparison_tool Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFuncti… CWE-79
Cross-site Scripting
CVE-2020-11499 2024-11-21 13:58 2020-04-3 Show GitHub Exploit DB Packet Storm